CVE-2020-7454: FreeBSD Kernel NAT Out-Of-Bounds Access Remote Code Execution Vulnerability
In FreeBSD 12.1-STABLE before r360971, 12.1-RELEASE before p5, 11.4-STABLE before r360971, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, libalias does not properly validate packet length resulting in modules causing an out of bounds read/write condition if no checking was built into the module.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of FreeBSD Kernel. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of NAT. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of kernel.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7454?
CVE-2020-7454 is a vulnerability in the FreeBSD Kernel that allows remote attackers to execute arbitrary code.
Is authentication required to exploit CVE-2020-7454?
No, authentication is not required to exploit this vulnerability.
How severe is CVE-2020-7454?
CVE-2020-7454 has a severity rating of 9.8, which is classified as critical.
How can I fix CVE-2020-7454?
To fix CVE-2020-7454, update to the latest version of FreeBSD Kernel and apply any available patches.
Where can I find more information about CVE-2020-7454?
You can find more information about CVE-2020-7454 in the FreeBSD Security Advisory (FreeBSD-SA-20:12.libalias.asc) and the ZeroDayInitiative advisories (ZDI-20-660 and ZDI-20-659).